vendor:
Image2PDF Converter
by:
Robbie Corley
7,2
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Image2PDF Converter
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 x64
2015
VeryPDF Image2PDF Converter SEH Buffer Overflow
The title parameter contained within the c:windowsImage2PDF.INI is vulnerable to a buffer overflow. This can be exploited using SEH overwrite. Instructions: 1. Run this sploit as-is. This will generate the new .ini file and place it in c:windows, overwriting the existing file 2. Run the Image2PDF program, hit [try], file --> add files 3. Open any .tif file. Here's the location of one that comes with the installation: C:Program Files (x86)VeryPDF Image2PDF v3.2trial.tif 4. Hit 'Make PDF', type in anything for the name of the pdf-to-be, and be greeted with your executed shellcode;
Mitigation:
Ensure that the Image2PDF program is updated to the latest version and that all security patches are applied.